CVE-2025-20798: High severity Google Android vulnerability
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5533.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20798?
CVE-2025-20798 has been classified as a medium to high severity vulnerability due to the risk of local privilege escalation.
How do I fix CVE-2025-20798?
To mitigate CVE-2025-20798, apply the patch identified by ALPS10315812 as soon as it becomes available.
Who is affected by CVE-2025-20798?
CVE-2025-20798 affects certain versions of Google Android, specifically 14.0, 15.0, and 16.0.
Can CVE-2025-20798 be exploited remotely?
CVE-2025-20798 requires local access to the system by a malicious actor for exploitation.
Is user interaction necessary for exploiting CVE-2025-20798?
No, user interaction is not needed to exploit CVE-2025-20798 once a malicious actor has system privilege.